OpenWrt
OpenWrt: Embedded operating system based on Linux secure by default
OpenWrt: Embedded operating system based on Linux secure by default
OPNsense is a FreeBSD-based open-source firewall and routing platform, forked from pfSense. It provides a web-based interface for stateful firewall rules, VPN (WireGuard, OpenVPN, IPsec), traffic shaping, intrusion detection via Suricata, and a plugin system.
No matches for those filters.
Your router sees every device and every connection in your home, yet stock firmware is often closed and rarely updated, quietly chatty in the bargain. Open-source firmware replaces it with code you can inspect and security you control, plus features the manufacturer never shipped. Because it runs on the one box every other device depends on, it is among the highest-leverage upgrades you can make. These are the trusted options.
Manufacturer firmware is a closed binary, so there is no setting that makes unauditable code trustworthy. It frequently goes years without a security update and sometimes phones home, and it may carry known holes you have no way to patch because you do not control the software. Tightening a few options in the admin page does not change what the firmware is allowed to do behind the interface. Since the router is the gateway for your whole network, that is the worst possible place for code you cannot see or maintain, and the only real fix is to replace it with firmware you can.
Every project here is judged against our public listing criteria, with weight on a healthy development pace and a clear flow of security updates, since an abandoned firmware is worse than the stock one it replaced. We favour broad, well-documented hardware support and open code that the community audits, from projects with a track record long enough to trust on the gateway. We note where a project suits a dedicated appliance versus a consumer router, so you can match it to what you own. A firmware earns a listing when it is actively maintained and genuinely inspectable.
Start with active development and timely security updates, because the firmware runs on hardware that stays online for years. Confirm support for your specific device before anything else, since a mismatch is the main way installs go wrong. Then weigh the features you will actually use, such as an encrypted DNS resolver and a VPN client, or network segmentation through VLANs. pfSense and OPNsense suit dedicated firewall hardware, while OpenWrt and LibreCMC cover many consumer routers. A strong community to lean on for setup matters as much as any single feature.
For most people who care about privacy, yes, with sensible care. Flashing carries a small chance of bricking the device, so confirm your exact model is supported and follow the project’s guide step by step rather than improvising. The payoff is large and durable: a router that keeps getting patched and that you control rather than the vendor. Because it sits on the gateway, it shields every device behind it at once, and that single upgrade outlasts the hardware it runs on. Set against the alternative of an unmaintained gateway sitting at the centre of your network, the modest risk of a careful flash is usually well worth taking.
Read the project’s page for your exact model first, and note the recovery procedure in case a flash stalls. Back up your current settings so you can rebuild quickly, then flash on a wired connection with an unhurried hour to spare. Configure the privacy features one at a time afterward, so you can tell what each one changed. Once the firmware is in place, point it at an encrypted DNS resolver and, if you use one, a VPN client, so the whole network benefits from a single configuration. The work is front-loaded; the protection it buys runs quietly for years afterward.